
The Changelog: Software Development, Open Source · Changelog Media
Securing npm is table stakes (Interview)
January 29, 2026·1 hr 21 min·6 clips
Adam identifies the structural problem: credit card companies have financial incentive to prevent fraud, but npm is a cost sink for Microsoft with no revenue tied to package integrity.
As heard by us
A sharp, grounded conversation about why npm security feels overdue, and why leaving npm is harder than wanting to.
NPM security lands here as infrastructure work, not routine cleanup. The episode frames the registry as a piece of JavaScript's everyday plumbing, then asks why GitHub's response still feels slower and thinner than the problem deserves.
Why you'd press play
Press play if you want to sit with npm's massive gravity and ask whether GitHub is moving fast enough to secure it.
Listen to the show on